PT-2026-22399 · Unknown · Http::Session2

Publicado

2026-02-27

·

Atualizado

2026-03-08

·

CVE-2018-25160

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions HTTP::Session2 versions through 1.09
Description The software does not properly validate user-provided session IDs, which could allow for code injection or other impacts depending on the session backend. For example, if memcached is used for session storage, an attacker might be able to inject memcached commands within the session ID value.
Recommendations Update to a version of HTTP::Session2 greater than 1.09.

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-25160

Produtos afetados

Http::Session2